The email looked like a court notice, came from a real Colombian mayor's office account, and gave the recipient three days to respond. Colombia's national CERT, COLCERT, says it was the opening of a Blind Eagle spearphishing campaign against public sector staff that ends with a remote access trojan running invisibly inside a legitimate Windows process.
In alert 119, issued on 25 September, COLCERT attributes the campaign with high confidence to Blind Eagle, also tracked as APT-C-36, and rates it an active threat to Colombian public entities. A follow-up technical report published on 26 September walks through the same chain and its final payload, Overlord RAT.
A court notice from a hijacked government inbox
According to the technical report, the email began circulating among public entities on 17 September. It impersonates the Third Court for the Execution of Sentences and Security Measures in Pitalito, Huila, and announces a lawsuit transfer with a three-day deadline. The sender is a genuine institutional account that had already been compromised, a mayor's office on the .gov.co domain in the sample COLCERT analysed. Because the sender is legitimate, the message passes reputation filters.
The attachment is not a document. It is an .xhtml file, really an SVG image carrying JavaScript, that uses HTML smuggling: it assembles its payload inside the victim's own browser rather than downloading anything suspicious. It builds a fake page for Colombia's Attorney General's Office (Fiscalía General de la Nación) and delivers a password-protected ZIP, with the password "THG2026" presented in the email as a case reference. Opening the script inside starts an eight-stage JavaScript, VBS and PowerShell chain.
A hidden desktop the victim never sees
The chain ends with Overlord RAT loaded only in memory inside RegSvcs.exe, a legitimate Windows component. COLCERT's alert says it gets there through process hollowing, swapping its own code into the legitimate process, and uses direct system calls to slip past most conventional EDR products. It persists through a registry Run key and a .vbs file in the Startup folder, so it survives reboots.
The implant gives the operator a hidden virtual desktop (HVNC), keylogging, clipboard and screen capture, audio recording, camera access, a remote console, and theft of cookies and passwords from Chrome, Edge, Brave, Opera and Firefox. COLCERT spells out why that matters: stolen session cookies let an attacker sign in to web services without passing the second authentication factor, and the hidden desktop lets them operate online banking from the victim's own machine and IP address.
COLCERT's sandbox analysis on 23 September confirmed three artifacts as malicious and surfaced a second command and control address not previously recorded. The alert also notes infrastructure shared with Quasar RAT.
Block port 4782 and hunt RegSvcs.exe traffic within 72 hours
COLCERT asks organisations to act within 72 hours:
- Block the C2 domain and IPs below in DNS, proxy and firewall, along with outbound traffic to port 4782/TCP.
- Search EDR data for any network connection started by RegSvcs.exe, and for wscript.exe executing .tmp files.
- Check user Startup folders for NetGuard*.vbs files, and look for manifest_*.xhtml files in %APPDATA%\Microsoft and C:\Users\Public.
Indicators
- envio14-9[.]duckdns[.]org, port 4782/TCP (resolving to 181[.]235[.]13[.]254 at the time of the report)
- 199[.]16[.]199[.]2, port 4782/TCP (newly identified C2)
- qsar20[.]duckdns[.]org, port 6001/TCP (shared Quasar RAT infrastructure)
- ZIP password: THG2026
This is the second time in two months COLCERT has publicly tied a campaign to Blind Eagle, the group with the longest running record of targeting Colombia. What changed is the delivery: legal pressure plus a genuine government sender is a combination a reputation filter cannot catch, which leaves the burden on the person reading the email. More on the group is on our APT-C-36 profile and our Colombia page.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.